In brief
- Cross-chain bridge Allbridge has paused its Core protocol after an attacker stole about $1.65 million from its Solana stablecoin liquidity pools.
- The attacker used a $1.12 million flash loan from lending protocol Kamino to skew the pools’ internal pricing, then extracted assets cheaply and bridged them to Ethereum.
- Allbridge told liquidity providers to withdraw and asked traders who profited from the resulting imbalance to return funds.
Cross-chain bridge Allbridge has paused its protocol after an attacker drained roughly $1.65 million from its Solana liquidity pools in a flash loan attack, according to blockchain security firms and the project itself.
Allbridge lets users move assets between blockchains that don’t natively communicate, and its Core product uses pools of native stablecoins such as USDC and USDT rather than minting wrapped tokens. On Sunday, the team said it had “paused the protocol as a precaution” while investigating, and urged liquidity providers to pull funds from affected pools.
In a follow-up tweet, Allbridge noted that its team was “preparing a detailed breakdown” and post-mortem report, adding that “There is no threat to users liquidity right now” as it works to relaunch Core without liquidity pools.
How it happened
Allbridge confirmed an earlier tweet from security firm PeckShield putting the loss at around $1.65 million, which noted that the attacker had bridged the funds from Solana to Ethereum.
Fellow firm CertiK detailed the method, which saw the attacker borrow $1.12 million through a flash loan from Solana lending protocol Kamino, before running a rapid series of stablecoin swaps to distort the internal accounting that prices assets in Allbridge’s pools.
With the pools mispriced, the attacker swapped a few thousand dollars of USDT for about $2.24 million in USDC before bridging the proceeds to an Ethereum address and scattering them across others. It isn’t clear how much remains within reach.
The manipulation left Allbridge’s pools lopsided, briefly letting other traders buy up the mispriced assets—a “temporary positive arbitrage window,” as the team put it. The DeFi platform asked anyone who profited from that window to send the money to a designated address, saying it would “go directly toward compensating affected LPs.” Its “goal is to return all affected funds,” the team added.
Not the first time
It’s the second time Allbridge has been caught this way. In April 2023, a similar flash-loan exploit drained around $573,000 from its BNB Chain pools; the project later said it recovered most of the funds and reworked how it calculates liquidity and withdrawals. Allbridge raised $2 million in 2022 to expand the bridge and fund security audits.
Bridges and the liquidity pools that feed them have long been among DeFi’s most-targeted infrastructure. More than $840 million was lost to DeFi hacks in just the first five months of 2026, with cross-chain systems repeatedly producing some of the largest single losses. Just last month, a bridge between Axelar and Secret Network was drained of $4.67 million after attackers exploited an “infinite mint” bug in a custom token contract.
Allbridge’s protocol remains paused, and how much of the $1.65 million can be clawed back will hinge on tracing the bridged funds—and on whether the arbitrage traders it appealed to actually send the money back.
Daily Debrief Newsletter
Start every day with the top news stories right now, plus original features, a podcast, videos and more.